You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure App Service上Node.js应用无法从Key Vault取密钥:无MSI凭证

Azure App Service(Linux)Node.js 20 LTS应用Key Vault密钥获取失败问题

在Azure App Service(Linux)上部署的Node.js 20 LTS应用,尝试从Azure Key Vault获取密钥时触发CredentialUnavailableError,错误信息为:

ManagedIdentityCredential: Authentication failed. Message ManagedIdentityCredential - No MSI credential available

相关代码片段

const { DefaultAzureCredential } = require("@azure/identity");
const { SecretClient } = require("@azure/keyvault-secrets");

const keyVaultName = process.env.KEY_VAULT_NAME;
const keyVaultUrl = `https://${keyVaultName}.vault.azure.net`;

async function loadSecrets() {
    try {
        require('dotenv').config();

        console.log('Starting loadSecrets function');
        console.log('NODE_ENV:', process.env.NODE_ENV);
        console.log('DATABASE_URL:', process.env.DATABASE_URL);
        console.log('KEY_VAULT_NAME:', process.env.KEY_VAULT_NAME);

        if (process.env.NODE_ENV === 'production') {
            console.log('Production environment detected. Attempting to load secrets from Key Vault.');

            console.log('Creating DefaultAzureCredential...');
            const credential = new DefaultAzureCredential();
            console.log('DefaultAzureCredential created successfully');

            const keyVaultUrl = `https://${process.env.KEY_VAULT_NAME}.vault.azure.net`;
            console.log('Key Vault URL:', keyVaultUrl);

            console.log('Creating SecretClient...');
            const secretClient = new SecretClient(keyVaultUrl, credential);
            console.log('SecretClient created successfully');

            console.log('Fetching secrets...');
            process.env.CLAUDE_API_KEY = (await secretClient.getSecret('CLAUDE-API-KEY')).value;
            console.log('CLAUDE-API-KEY fetched successfully');

            // ... [other secret fetching operations] ...

            console.log('All secrets loaded successfully from Key Vault');
        } else {
            console.log('Non-production environment. Skipping Key Vault secret loading.');
        }
    } catch (error) {
        console.error('Error in loadSecrets function:');
        console.error('Error name:', error.name);
        console.error('Error message:', error.message);
        // ... [additional error logging] ...
        throw error;
    }
}

// Load secrets before starting the server
loadSecrets().then(() => {
    // Server setup and route definitions...
}).catch(error => {
    console.error('Failed to load secrets:', error);
    process.exit(1);
});

已执行的排查操作

  • 确认App Service已启用系统分配托管身份
  • 已为该托管身份在Key Vault的IAM中分配“Key Vault Secrets User”角色(Key Vault采用RBAC权限模型)
  • 验证App Service配置中KEY_VAULT_NAME环境变量已正确设置
  • 尝试改用DefaultAzureCredential替代ManagedIdentityCredential
  • 确认Key Vault中存在对应名称的密钥

疑问

  • 为何已启用托管身份仍出现“No MSI credential available”错误?
  • 是否存在遗漏的配置或权限项?
  • 如何排查托管身份的认证流程?
  • Node.js 20 LTS与Azure Identity SDK是否存在已知兼容问题?
  • 如何在运行时验证托管身份与App Service的关联状态?

内容的提问来源于stack exchange,提问作者user26559929

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.20 06:43:19